## Tool permissions and approvals

A tangent’s identity tells you which worker you are addressing\.&#32;It does not yet explain why one of that worker’s calls ran without asking\,&#32;why another stopped before a dialog\,&#32;or why an approved write still failed\.

This part makes permission resolution an operator skill rather than an extension\-author prerequisite\.&#32;Start with the exact operation\,&#32;follow its applicable policy\,&#32;and keep permission separate from execution and effects\.

### Read the three desks in sequence

**Approval Desk**&#32;establishes the tier matrix\,&#32;then works through conflicts among explicit tool policy\,&#32;effective user policy\,&#32;mode defaults\,&#32;and ordered bash rules\.&#32;Its command strings are classification data only\.

**Dispatch Desk**&#32;follows a&#32;`write`&#32;envelope into the fictional&#32;`seed_slot`&#32;device\.&#32;You will distinguish generic write policy from device policy\,&#32;an outer admission from an inner check\,&#32;and two prompts from two executions\.

**Boundary Desk**&#32;explains the actual one\-call Approve\/Deny choice\,&#32;dismissal and unavailable UI\,&#32;RPC and ACP capability differences\,&#32;launch precedence\,&#32;and the later OS\/host boundary\.&#32;It also connects Task and Tan construction to the yolo\-default settings helper without pretending that a conversation fork clones every safeguard\.

The public starting points are&#32;[Approval Desk’s cases](<https://present-sketch-tp94.here.now/examples/approval-desk/cases.json>)\,&#32;[Dispatch Desk’s cases](<https://present-sketch-tp94.here.now/examples/dispatch-desk/cases.json>)\,&#32;and&#32;[Boundary Desk’s cases](<https://present-sketch-tp94.here.now/examples/boundary-desk/cases.json>)\.&#32;They are inert JSON\,&#32;not configuration to install or tools to submit\.&#32;The recording actions change no real inventory or publication service\.

### Keep the default route on paper

Predict\,&#32;inspect\,&#32;explain\,&#32;and compare with the supplied recorded outcomes\.&#32;No provider call\,&#32;credentials\,&#32;personal settings change\,&#32;remote connection\,&#32;privileged broker\,&#32;or executable simulator is required\.&#32;Browser milestone selection changes reading state only\.

The source snapshot and new evidence are dated 30 August 2026\.&#32;The two existing focused test runs\,&#32;the separate private scenario report\,&#32;and the installed configuration CLI observation retain distinct scopes\.&#32;Use&#32;[Evidence and limitations](<https://present-sketch-tp94.here.now/chapters/permissions-evidence-and-limitations>)&#32;before promoting a passing classification into a claim about physical UI or OS enforcement\.
